Claude Mythos
| Claude Mythos | |
|---|---|
| Developer | Anthropic |
| Release | April 7, 2026 |
| Stable release | Claude Mythos 5 / June 9, 2026 |
| Type | |
| License | Proprietary |
Claude Mythos is a large language model developed by Anthropic to find software vulnerabilities. Anthropic has not officially released the model to the public, citing safety and misuse concerns.[1] Reactions to Claude Mythos were immediate and mixed.[2]
History
[edit]Leak (March 26, 2026 – April 7, 2026)
[edit]The existence of a model named Claude Mythos had become publicly known on March 26, 2026 due to leaked blog post drafts.[3] Anthropic later acknowledged the development of Mythos to Fortune, and said that the model presented significant risks to cybersecurity.[4] According to Axios, Anthropic had issued a warning about Mythos's capabilities to government officials that month.[5]
Launch (April 7, 2026 – present)
[edit]Anthropic publicly disclosed Mythos on April 7.[6] The company stated that it had no plan to release Mythos to the public.[7] It instead launched Project Glasswing, with a consortium of companies using Mythos to find and fix software vulnerabilities. Over forty companies were granted access, including Microsoft, Apple, Google, Amazon Web Services, the Linux Foundation, Cisco, Nvidia, and Broadcom.[8] That day, several unauthorized users gained access to Mythos, according to Bloomberg News.[9]
Reportedly, a few users in a private Discord channel gained access to Mythos the same day it was announced, using details from the recent Mercor data breach.[9] The NSA has also used Mythos, despite the fact that the DoD, its parent organization, had blacklisted Anthropic after a dispute.[10] In April 2026, the Chinese government requested access to Mythos, but was rebuffed.[11]
On June 2, Anthropic expanded access to its Claude Mythos cyber-security model, making it available to 150 organizations in more than 15 countries.[12] This includes several organizations in India.[13]
In its May 28, 2026 announcement of Claude Opus 4.8, Anthropic stated it expected to make "Mythos-class" models available to all customers within weeks of the announcement, pending the development of additional cybersecurity safeguards.[14]
On June 9, Anthropic released Claude Mythos 5 as a preview via Project Glasswing alongside a version of Mythos with extended safeguards titled Fable 5.[15]
On June 12, Anthropic revoked access to Claude Mythos 5 and Fable 5 due to a US government export control directive citing national security concerns.[16]
Specifications and capabilities
[edit]Claude Mythos Preview is a large language model designed to fix vulnerabilities within software.[17][2] The UK AI Security Institute tested Claude Mythos with a cyber range. Claude Mythos ranked highest, with Claude Opus 4.6 coming in second, followed by a tie between GPT-5.4 and GPT-5.3 Codex.[18]
Vulnerabilities found
[edit]Anthropic stated that Mythos had found vulnerabilities in "every major operating system and every major web browser" in its testing.[19] Two weeks after the limited release, Mozilla announced that it had found and patched 271 security vulnerabilities in Firefox using Mythos Preview.[20][21] On May 14, 2026, employees at Calif.io announced they had used Mythos to create a memory corruption exploit affecting Apple M5 chips.[22]
Responses
[edit]Media response
[edit]Thomas Fraise, writing for The Conversation, argued that Mythos could ruin nuclear deterrence.[23] Brett J. Goldstein, writing for The New York Times, argued that the model puts individuals and smaller teams at a "cybersecurity disadvantage".[24]
Some Chinese media outlets viewed Mythos positively, defending Anthropic's decisions.[25]
Financial response
[edit]Hours after Anthropic publicly revealed Mythos, U.S. secretary of the treasury Scott Bessent and Federal Reserve chair Jerome Powell convened financial executives to issue a warning on Mythos's capabilities.[26] Several banks began testing Mythos at their behest, including JPMorgan Chase, Goldman Sachs, Citigroup, Bank of America, and Morgan Stanley.[27] The Bank of Canada summoned major lenders to a similar meeting the following day.[28] Mythos was scheduled to be discussed by the Bank of England's Cross Market Operational Resilience Group and CMORG AI Taskforce meetings.[29]
European Central Bank president Christine Lagarde praised Anthropic for limiting access to Mythos.[30] In response to European banks that were not given access to Mythos, Mistral AI began developing its own model.[31]
Governmental responses
[edit]On April 14, 2026, Bloomberg reported that the United States Department of the Treasury was seeking access to Claude Mythos.[32] On April 16, the White House and Anthropic held a meeting about Mythos.[33] On May 13, a bipartisan group of 32 US Representatives wrote to the Office of the National Cyber Director (ONCD) on revisiting the U.S.'s federal cybersecurity policy.[34][35]
On April 23, Nirmala Sitharaman, chair of India's Ministry of Finance held a meeting of banks and government officials to discuss potential new cybersecurity threats following the release of Mythos.[36]
At a joint public-private meeting hosted by Japan's Financial Services Agency on April 24, participants agreed to form a work-group to counter potential threats caused by Mythos.[37]
After an April meeting with officials from Anthropic, Evan Solomon, the Canadian minister of artificial intelligence and digital innovation, praised Anthropic for limiting access to Mythos.[38]
Several meetings with banks were held by the Australian Prudential Regulation Authority in response to Mythos.[39]
In April 2026, Anthropic declined to give access to Claude Mythos to the Chinese government after a request from a Chinese think tank.[11]
References
[edit]- ^ "What is Claude Mythos and what risks does it pose?". BBC News. 18 April 2026. Retrieved 2026-05-30.
- ^ a b Metz, Cade; Conger, Kate Conger (2026-05-12). "Is Anthropic's New A.I. Really That Scary? It Depends Whom You Ask". The New York Times. ISSN 0362-4331. Retrieved 2026-05-17.
- ^ Nolan, Beatrice (March 26, 2026). "Exclusive: Anthropic left details of an unreleased model, an upcoming exclusive CEO event, in a public database". Fortune. Archived from the original on March 27, 2026. Retrieved April 7, 2026.
- ^ Nolan, Beatrice (March 26, 2026). "Anthropic acknowledges testing new AI model representing 'step change' in capabilities, after accidental data leak reveals its existence". Fortune. Retrieved May 18, 2026.
- ^ VandeHei, Jim (March 29, 2026). "AI's looming cyber nightmare". Axios. Retrieved May 18, 2026.
- ^ Roose, Kevin (April 7, 2026). "Anthropic Claims Its New A.I. Model, Mythos, Is a Cybersecurity 'Reckoning'". The New York Times. Retrieved May 18, 2026.
- ^ McMillan, Robert (April 7, 2026). "Anthropic Set to Preview Powerful 'Mythos' Model to Ward Off AI Cyberthreats". The Wall Street Journal. Retrieved May 18, 2026.
- ^ Newman, Lily (April 7, 2026). "Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything". Wired. Retrieved May 18, 2026.
- ^ a b Metz, Rachel (April 21, 2026). "Anthropic's Mythos Model Is Being Accessed by Unauthorized Users". Bloomberg News. Retrieved May 18, 2026.
- ^ "Scoop: NSA using Anthropic's Mythos despite Defense Department blacklist". Axios. 2026-04-19. Retrieved 2026-04-22.
- ^ a b Volz, Dustin; Barnes, Julian E.; Frenkel, Sheera; Mickle, Tripp (2026-05-12). "China Sought Access to Anthropic's Newest A.I. The Answer Was No". The New York Times. ISSN 0362-4331. Retrieved 2026-05-12.
- ^ Murgia, Madhumita (June 2, 2026). "Anthropic to expand Mythos access to more than 15 countries". The Financial Times.
- ^ "India Joins Anthropic's Global Cybersecurity Initiative With Access To Claude Mythos". Knowledge and News Network. June 4, 2026.
- ^ "Introducing Claude Opus 4.8". www.anthropic.com. Retrieved 2026-06-06.
- ^ Nickel, Dana; Miller, Maggie (2026-06-09). "Anthropic releases a less-powerful version of its most advanced model". Politico. Retrieved 2026-06-10.
- ^ Capoot, Ashley (2026-06-13). "Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive". CNBC. Retrieved 2026-06-13.
- ^ Criddle, Cristina (April 7, 2026). "Anthropic rolls out cyber AI model days after source code leak". Financial Times. Retrieved May 18, 2026.
- ^ "Our evaluation of Claude Mythos Preview's cyber capabilities | AISI Work". AI Security Institute. 13 April 2026. Retrieved 22 April 2026.
- ^ Murphy, Margi (April 7, 2026). "Anthropic Limits Mythos Model Release in Bid to Stave Off Hacks". Bloomberg News. Retrieved May 18, 2026.
- ^ Orland, Kyle (21 April 2026). "Mozilla: Anthropic's Mythos found 271 security vulnerabilities in Firefox 150". Ars Technica. Retrieved 22 April 2026.
- ^ Newman, Lily Hay (21 April 2026). "Mozilla Used Anthropic's Mythos to Find and Fix 271 Bugs in Firefox". WIRED. Retrieved 22 April 2026.
- ^ Schroeder, Stan (2026-05-15). "Anthropic's Mythos is already finding security flaws in Apple software". Mashable. Retrieved 2026-05-17.
- ^ Fraise, Thomas (2026-05-12). "Hacking the bomb? What Claude Mythos AI reveals about the gamble of nuclear deterrence". The Conversation. Retrieved 2026-05-17.
- ^ Goldstein, Brett J. (2026-04-28). "Opinion | Your Passwords Are Probably Screwed". The New York Times. ISSN 0362-4331. Retrieved 2026-05-17.
- ^ Zhang, Irene. "Claude Mythos: China Reacts". www.chinatalk.media. Retrieved 2026-05-17.
- ^ Gillespie, Todd; Johnson, Katanga; Levitt, Hannah; Natarajan, Sridhar (April 9, 2026). "Anthropic Model Scare Sparks Urgent Bessent, Powell Warning to Bank CEOs". Bloomberg News. Retrieved May 18, 2026.
- ^ Robertson, Jordan; Gillespie, Todd; Natarajan, Sridhar (April 10, 2026). "Wall Street Banks Try Out Anthropic's Mythos as US Urges". Bloomberg News. Retrieved May 18, 2026.
- ^ Hertzberg, Erik; Dobby, Christine (April 10, 2026). "Bank of Canada, Major Lenders Met on Anthropic AI Cyber Risk". Bloomberg News. Retrieved May 18, 2026.
- ^ Rees, Tom (April 11, 2026). "Bank of England Set to Discuss Anthropic's Mythos With Banks". Bloomberg News. Retrieved May 18, 2026.
- ^ Lacqua, Francine; Stirling, Craig (April 14, 2026). "Lagarde, Worried About AI, Lauds Anthropic's Approach on Mythos". Bloomberg News. Retrieved May 18, 2026.
- ^ Cohen, Claudia; Berthelot, Benoit (May 13, 2026). "Mistral Developing New AI Model for Banks Lacking Mythos Access". Bloomberg News. Retrieved May 18, 2026.
- ^ Murphy, Margi; Metz, Rachel (April 14, 2026). "US Treasury Seeking Access to Anthropic's Mythos to Find Flaws". Bloomberg News. Retrieved May 18, 2026.
- ^ "White House and Anthropic hold 'productive' meeting amid fears over Mythos model". BBC. 2026-04-18. Retrieved 2026-05-17.
- ^ Gold, Ashley (2026-05-13). "Scoop: Lawmakers press White House to act on AI cyber threats". Axios. Retrieved 2026-05-17.
- ^ "AI-Discovered Vulnerability Coordination Letter" (PDF). house.gov. 13 May 2026. Retrieved 30 May 2026.
- ^ "If AI Can Hack Faster Than Humans, What Happens Next?". Forbes India. 24 April 2026. Retrieved 17 May 2026.
- ^ "Japan rushing to counter threat of cyberattack from Mythos AI model". The Asahi Shimbun. 27 April 2026. Retrieved 17 May 2026.
- ^ Hertzberg, Erik (April 14, 2026). "Anthropic Wins Accolades From Canada's AI Minister Over Mythos Approach". Bloomberg News. Retrieved May 18, 2026.
- ^ Eyers, James (2026-04-29). "APRA meets with banks, urges more vigilance against AI-powered hacks". Australian Financial Review. Retrieved 2026-05-17.
External links
[edit]- Official website
- Claude Fable 5 and Claude Mythos 5 – announcement article on Anthropic's website